Skip to main content 홈 크리에이터 rohunj claude-build-workflow pytm
pytm Python-based threat modeling using pytm library for programmatic STRIDE analysis, data flow diagram generation, and automated security threat identification. Use when: (1) Creating threat models programmatically using Python code, (2) Generating data flow diagrams (DFDs) with automatic STRIDE threat identification, (3) Integrating threat modeling into CI/CD pipelines and shift-left security practices, (4) Analyzing system architecture for security threats across trust boundaries, (5) Producing threat reports with STRIDE categories and mitigation recommendations, (6) Maintaining threat models as code for version control and automation.
설치로 이동 Skills Marketplace 커뮤니티가 만든 AI 스킬을 발견하고 탐색하세요.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/rohunj/claude-build-workflow --skill pytm명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
Zip 다운로드 다운로드 중... 이 저장소의 다른 Skills Convert bug reports into prd.json user stories for autonomous fixing. Use after running test-and-break skill. Triggers on: convert bugs to stories, fix these bugs, add bugs to prd, create fix stories.
vercel-react-best-practices React and Next.js performance optimization guidelines from Vercel Engineering. This skill should be used when writing, reviewing, or refactoring React/Next.js code to ensure optimal performance patterns. Triggers on tasks involving React components, Next.js pages, data fetching, bundle optimization, or performance improvements.
Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping. Use when: (1) Scanning code for security vulnerabilities across multiple languages, (2) Performing security code reviews with pattern-based detection, (3) Integrating SAST checks into CI/CD pipelines, (4) Providing remediation guidance with OWASP Top 10 and CWE mappings, (5) Creating custom security rules for organization-specific patterns, (6) Analyzing dependencies for known vulnerabilities.
name pytm description Python-based threat modeling using pytm library for programmatic STRIDE analysis, data flow diagram generation, and automated security threat identification. Use when: (1) Creating threat models programmatically using Python code, (2) Generating data flow diagrams (DFDs) with automatic STRIDE threat identification, (3) Integrating threat modeling into CI/CD pipelines and shift-left security practices, (4) Analyzing system architecture for security threats across trust boundaries, (5) Producing threat reports with STRIDE categories and mitigation recommendations, (6) Maintaining threat models as code for version control and automation.
version 0.1.0 maintainer SirAppSec category threatmodel tags ["threat-modeling","stride","dfd","security-architecture","pytm","appsec","risk-analysis"] frameworks ["STRIDE","OWASP","MITRE-ATT&CK","NIST"] dependencies {"python":">=3.7","packages":["pytm","graphviz"]} references ["https://github.com/izar/pytm","https://owasp.org/www-community/Threat_Modeling","https://www.microsoft.com/en-us/security/blog/2007/09/11/stride-chart/","https://attack.mitre.org/"]
Threat Modeling with pytm
Overview
pytm is a Python library for programmatic threat modeling based on the STRIDE methodology. It enables
security engineers to define system architecture as code, automatically generate data flow diagrams (DFDs),
identify security threats across trust boundaries, and produce comprehensive threat reports. This
approach integrates threat modeling into CI/CD pipelines, enabling shift-left security and continuous
threat analysis.
Quick Start
Create a basic threat model:
from pytm import TM, Server, Dataflow, Boundary, Actor
tm = TM("Web Application Threat Model" )
tm.description = "E-commerce web application"
internet = Boundary("Internet" )
dmz = Boundary("DMZ" )
internal = Boundary("Internal Network" )
user = Actor("Customer" )
user.inBoundary = internet
web = Server("Web Server" )
web.inBoundary = dmz
db = Server("Database" )
db.inBoundary = internal
user_to_web = Dataflow(user, web, "HTTPS Request" )
user_to_web.protocol = "HTTPS"
user_to_web.data = "credentials, payment info"
user_to_web.isEncrypted = True
web_to_db = Dataflow(web, db, "Database Query" )
web_to_db.protocol = "SQL/TLS"
web_to_db.data = "user data, transactions"
tm.process()
Install pytm:
pip install pytm
brew install graphviz
Core Workflows
Workflow 1: Create New Threat Model
Progress:
[ ] 1. Define system scope and trust boundaries
[ ] 2. Identify all actors (users, administrators, external systems)
[ ] 3. Map system components (servers, databases, APIs, services)
[ ] 4. Define data flows between components with security attributes
[ ] 5. Run to generate threats and DFD
[ ] 6. Review STRIDE threats and add mitigations
[ ] 7. Generate threat report with
tm.process()
scripts/generate_report.py
Work through each step systematically. Check off completed items.
Workflow 2: STRIDE Threat Analysis pytm automatically identifies threats based on STRIDE categories:
Spoofing : Identity impersonation attacks
Tampering : Unauthorized modification of data
Repudiation : Denial of actions without traceability
Information Disclosure : Unauthorized access to sensitive data
Denial of Service : Availability attacks
Elevation of Privilege : Unauthorized access escalation
For each identified threat:
Review threat description and affected component
Assess likelihood and impact (use references/risk_matrix.md)
Determine if existing controls mitigate the threat
Add mitigation using threat.mitigation = "description"
Document residual risk and acceptance criteria
Workflow 3: Architecture as Code Define system architecture programmatically:
from pytm import TM, Server, Datastore, Dataflow, Boundary, Actor, Lambda
tm = TM("Microservices Architecture" )
internet = Boundary("Internet" )
cloud_vpc = Boundary("Cloud VPC" )
api_gateway = Server("API Gateway" )
api_gateway.inBoundary = cloud_vpc
api_gateway.implementsAuthentication = True
api_gateway.implementsAuthorization = True
auth_service = Lambda("Auth Service" )
auth_service.inBoundary = cloud_vpc
order_service = Lambda("Order Service" )
order_service.inBoundary = cloud_vpc
user_db = Datastore("User Database" )
user_db.inBoundary = cloud_vpc
user_db.isEncryptedAtRest = True
client_to_api = Dataflow(Actor("Client" ), api_gateway, "API Request" )
client_to_api.protocol = "HTTPS"
client_to_api.isEncrypted = True
client_to_api.data = "user credentials, orders"
api_to_auth = Dataflow(api_gateway, auth_service, "Auth Check" )
api_to_auth.protocol = "gRPC/TLS"
auth_to_db = Dataflow(auth_service, user_db, "User Lookup" )
auth_to_db.protocol = "TLS"
tm.process()
Workflow 4: CI/CD Integration Automate threat modeling in continuous integration:
name: Threat Model Analysis
on: [push , pull_request ]
jobs:
threat-model:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Set up Python
uses: actions/setup-python@v4
with:
python-version: '3.10'
- name: Install dependencies
run: |
pip install pytm
sudo apt-get install -y graphviz
- name: Generate threat model
run: python threat_model.py
- name: Upload DFD diagram
uses: actions/upload-artifact@v3
with:
name: threat-model-dfd
path: '*.png'
- name: Check for unmitigated threats
run: python scripts/check_mitigations.py threat_model.py
Workflow 5: Threat Report Generation Generate comprehensive threat documentation:
python threat_model.py
./scripts/generate_report.py --model threat_model.py --output threat_report.md
./scripts/generate_report.py --model threat_model.py --format json --output threats.json
System architecture overview
Trust boundary analysis
Complete STRIDE threat enumeration
Existing and recommended mitigations
Risk prioritization matrix
Security Considerations
Sensitive Data Handling
Threat models as code : Store in version control but review for sensitive architecture details
Credentials and secrets : Never hardcode in threat models - use placeholders
Data classification : Clearly label data flows with sensitivity levels (PII, PCI, PHI)
Report distribution : Control access to threat reports revealing security architecture
Access Control
Threat model repository : Restrict write access to security team and architects
CI/CD integration : Protect threat modeling pipeline from tampering
Diagram artifacts : Control distribution of DFDs showing system architecture
Mitigation tracking : Integrate with secure issue tracking systems
Audit Logging Log the following for security governance:
Threat model creation and modification history
Identified threats and severity assessments
Mitigation implementation and validation
Risk acceptance decisions with approval
Threat model review and update cycles
Compliance Requirements
NIST 800-30 : Risk assessment methodology alignment
ISO 27001 : A.14.1.2 - Securing application services on public networks
OWASP SAMM : Threat Assessment practice maturity
PCI-DSS 6.3.1 : Security threat identification in development
SOC2 CC9.1 : Risk assessment process for system changes
Bundled Resources
Scripts (scripts/)
generate_report.py - Generate markdown/JSON threat reports with STRIDE categorization
check_mitigations.py - Validate all identified threats have documented mitigations
threat_classifier.py - Classify threats by severity using DREAD or custom risk matrix
template_generator.py - Generate threat model templates for common architectures
References (references/)
stride_methodology.md - Complete STRIDE methodology guide with threat examples
risk_matrix.md - Risk assessment framework with likelihood and impact scoring
component_library.md - Reusable pytm components for common patterns (APIs, databases, cloud services)
mitigation_strategies.md - Common mitigation patterns mapped to STRIDE categories and OWASP controls
Assets (assets/)
templates/web_application.py - Web application threat model template
templates/microservices.py - Microservices architecture template
templates/mobile_app.py - Mobile application threat model template
templates/iot_system.py - IoT system threat model template
dfd_styles.json - Custom graphviz styling for professional diagrams
Common Patterns
Pattern 1: Web Application Three-Tier Architecture from pytm import TM, Server, Datastore, Dataflow, Boundary, Actor
tm = TM("Three-Tier Web Application" )
internet = Boundary("Internet" )
dmz = Boundary("DMZ" )
internal = Boundary("Internal Network" )
user = Actor("End User" )
user.inBoundary = internet
lb = Server("Load Balancer" )
lb.inBoundary = dmz
lb.implementsNonce = True
web = Server("Web Server" )
web.inBoundary = dmz
web.implementsAuthentication = True
web.implementsAuthenticationOut = False
app = Server("Application Server" )
app.inBoundary = internal
app.implementsAuthorization = True
db = Datastore("Database" )
db.inBoundary = internal
db.isSQL = True
db.isEncryptedAtRest = True
Dataflow(user, lb, "HTTPS" ).isEncrypted = True
Dataflow(lb, web, "HTTPS" ).isEncrypted = True
Dataflow(web, app, "HTTP" ).data = "session token, requests"
Dataflow(app, db, "SQL/TLS" ).data = "user data, transactions"
tm.process()
Pattern 2: Cloud Native Microservices from pytm import TM, Lambda, Datastore, Dataflow, Boundary, Actor
tm = TM("Cloud Microservices" )
cloud = Boundary("Cloud Provider VPC" )
user = Actor("Mobile App" )
api_gateway = Lambda("API Gateway" )
api_gateway.inBoundary = cloud
api_gateway.implementsAPI = True
auth_fn = Lambda("Auth Function" )
auth_fn.inBoundary = cloud
cache = Datastore("Redis Cache" )
cache.inBoundary = cloud
cache.isEncrypted = True
db = Datastore("DynamoDB" )
db.inBoundary = cloud
db.isEncryptedAtRest = True
Dataflow(user, api_gateway, "API Call" ).protocol = "HTTPS"
Dataflow(api_gateway, auth_fn, "Auth" ).protocol = "internal"
Dataflow(auth_fn, cache, "Session" ).isEncrypted = True
Dataflow(api_gateway, db, "Query" ).isEncrypted = True
tm.process()
Pattern 3: Adding Custom Threats Define organization-specific threats:
from pytm import TM, Threat
tm = TM("Custom Threat Model" )
web_server = Server("Web Server" )
custom_threat = Threat(
target=web_server,
id ="CUSTOM-001" ,
description="API rate limiting bypass using distributed requests" ,
condition="web_server.implementsRateLimiting is False" ,
mitigation="Implement distributed rate limiting with Redis" ,
references="OWASP API Security Top 10 - API4 Unrestricted Resource Consumption"
)
web_server.threats.append(custom_threat)
Pattern 4: Trust Boundary Analysis Focus on cross-boundary threats:
for flow in tm.dataflows:
if flow.source.inBoundary != flow.sink.inBoundary:
print (f"Cross-boundary flow: {flow.name} " )
print (f" From: {flow.source.inBoundary.name} " )
print (f" To: {flow.sink.inBoundary.name} " )
print (f" Encrypted: {flow.isEncrypted} " )
print (f" Authentication: {flow.implementsAuthentication} " )
Trust boundary crossings require extra scrutiny:
Authentication and authorization mechanisms
Encryption in transit
Input validation and sanitization
Logging and monitoring
Integration Points
SDLC Integration
Design Phase : Create initial threat model during architecture review
Development : Reference threat model for security requirements
Code Review : Validate mitigations are implemented correctly
Testing : Generate security test cases from identified threats
Deployment : Validate security controls match threat model assumptions
Operations : Update threat model for infrastructure changes
Security Tools Ecosystem
Issue Tracking : Export threats as Jira/GitHub issues for mitigation tracking
Documentation : Generate threat models for security documentation
SIEM : Map threats to detection rules and monitoring alerts
Pentesting : Provide threat model to pentesters for targeted assessment
Code Analysis : Link SAST/DAST findings to threat model threats
Cloud and DevOps
Infrastructure as Code : Threat model Terraform/CloudFormation templates
Container Security : Model container orchestration and service mesh
API Design : Threat model API gateway and microservices communication
Secrets Management : Model key management and secrets distribution
Troubleshooting
Issue: Missing Threats in Output Symptoms : Expected STRIDE threats not appearing in generated report
Verify component properties are set correctly (e.g., isSQL=True for databases)
Check data flow security attributes (isEncrypted, protocol)
Ensure components are assigned to boundaries
Review trust boundary crossings
Consult references/stride_methodology.md for threat conditions
Issue: Diagram Generation Failure Symptoms : DFD not generated or graphviz errors
dot -V
brew install graphviz
sudo apt-get install graphviz
python -c "from pytm import TM; tm = TM('test'); tm.process()"
Issue: Too Many False Positive Threats Symptoms : Identified threats don't apply to your architecture
Set accurate component properties to suppress irrelevant threats
Use threat conditions to filter: threat.condition = "..."
Document why threats don't apply: threat.mitigation = "N/A - using managed service"
Create custom threat library with references/component_library.md
Issue: Threat Model Maintenance Drift Symptoms : Threat model doesn't reflect current architecture
Store threat models in version control alongside architecture diagrams
Trigger threat model regeneration in CI on architecture changes
Schedule quarterly threat model reviews
Link threat model updates to architecture review board approvals
Use scripts/check_mitigations.py to validate completeness
Advanced Configuration
Custom Threat Definitions Create organization-specific threat library:
from pytm import Threat
def add_custom_threats (tm ):
"""Add organization-specific threats to threat model"""
cloud_misconfiguration = Threat(
id ="CLOUD-001" ,
description="Misconfigured cloud storage bucket exposes sensitive data" ,
condition="datastore.inBoundary.name == 'Cloud' and not datastore.isEncrypted" ,
mitigation="Enable encryption at rest and bucket policies"
)
api_abuse = Threat(
id ="API-001" ,
description="API endpoint abuse through lack of rate limiting" ,
condition="server.implementsAPI and not server.implementsRateLimiting" ,
mitigation="Implement rate limiting and API key rotation"
)
return [cloud_misconfiguration, api_abuse]
Risk Scoring Integration Add DREAD scoring to threats:
class ScoredThreat (Threat ):
def __init__ (self, *args, **kwargs ):
super ().__init__(*args, **kwargs)
self .damage = 0
self .reproducibility = 0
self .exploitability = 0
self .affected_users = 0
self .discoverability = 0
def dread_score (self ):
return (self .damage + self .reproducibility + self .exploitability +
self .affected_users + self .discoverability) / 5
threat = ScoredThreat(
target=component,
description="SQL Injection" ,
damage=9 ,
reproducibility=8 ,
exploitability=7 ,
affected_users=10 ,
discoverability=6
)
print (f"DREAD Score: {threat.dread_score()} /10" )
Diagram Customization Customize DFD output with graphviz attributes:
internet.color = "red"
dmz.color = "orange"
internal.color = "green"
tm.graph_options = {
"rankdir" : "LR" ,
"bgcolor" : "white" ,
"fontname" : "Arial" ,
"fontsize" : "12"
}
References